Earlier quoted context omitted.
The important thing for all of us to remember, is that in any given conversation we may be idiot. Until I'm sure the other person doesn't know what they're talking about, I try and assume they're right.
> The important thing for all of us to remember, is that in any given conversation we may be idiot. Alternative take, particularly pertinent to this situation: The person handling twitter is not a technical person, but a customer support person who handles hundreds of dumb questions, day in, day out, from customers who have no clue what they're doing but will often throw technical terms around. Expecting solid techni…
HTTPS on Your Landing Page Is Important
201–210 of 307 posts
Re: HTTPS on Your Landing Page Is Important
#202Bare in mind, on their complaints page you can download a complaints Word document, fully capable of having embedded VB script [2].
Also, it took them _months_ to sort out an issue where they would only check for 3 numbers (pin) and 3 letters (password), always asking for the first, second and third characters.
Also-also, I remember a while back not being able to access my card (for about a day) because a single engineer accidentally corrupted their main database.
[1] http://financial-ombudsman.org.uk
[2] http://financial-ombudsman.org.uk/consumer/complaints.htm
Re: HTTPS on Your Landing Page Is Important
#203It's 2017, and my social media account is protected by a tamper-proof phish-resistant embedded-encryption U2F microcontroller dongle, in addition to a password of virtually unlimited length and charset. Meanwhile, my bank has a max password length of 12 and I can only use an alphabet of roughly 64 characters. The future is here folks. And it sucks.
My bank only recently upgraded max password length from 8 to 12. Oh, and no special characters please.
Re: HTTPS on Your Landing Page Is Important
#204It's 2017, and my social media account is protected by a tamper-proof phish-resistant embedded-encryption U2F microcontroller dongle, in addition to a password of virtually unlimited length and charset. Meanwhile, my bank has a max password length of 12 and I can only use an alphabet of roughly 64 characters. The future is here folks. And it sucks.
> my bank has a max password length of 12 Look at Mr. PrivateBanking over there, my one is 5. Amount in words : Five. And that is after they updated all their software and moved to a new datacenter and everything recently. Granted I have a hardware dongle to authenticate any transactions , but to gain access to all my information, five characters is all the protection they wish to offer...
Re: HTTPS on Your Landing Page Is Important
#205I'm not really surprised, UK banks are absolutely terrible in terms of their product and even worse in supporting clients having valid points. Another example would be MetroBank that recently changed password prompt to a masked password prompt (in addition to already existing masked PIN alongside) ignoring the research proving its a horrible user experience and in fact lowers the security or (not a bank, but still ma…
Re: HTTPS on Your Landing Page Is Important
#206Earlier quoted context omitted.
Couldn't "private" also not mean "private"? For instance: when you're on Facebook, couldn't people think they are exchanging private messages because the address bar says "private"? "secure" means "secure connection" to me, and it sounds perfectly appropriate. Maybe you can't find a better term for "secure" because it's perfectly fine, already..?
> Maybe you can't find a better term for "secure" because it's perfectly fine, already..? Could be! Someone else suggested "Encrypted", seems like a good word. I really don't know.
I'm thinking specially in its inactive "not encrypted" version, where people aren't going to appreciate the gravity of a page being "not encrypted".
I bet the folks at Google already thought about this through.
Re: HTTPS on Your Landing Page Is Important
#207A bit side topic: It seems that every time Troy interacts with a company on Twitter, they never seem to click on to who he is, until it's probably too late and they look like fools. It's just so amusing to see companies trying to condescend to Troy, when he's one of the most visible authorities on web security on the planet (not necessarily the most authoritative, but the most well known). I occasionally get this whe…
This being NatWest the penny probably still hasn’t dropped, and they’re probably trying to get him arrested for “hacking our internet”. I doubt they’ll actually implement a change. The general approach in the UK has been to not blame banks at all for poor security, and to punish anyone who finds a security issue severely.
There's a number of places in that chain of events that something could go nastily wrong, despite them owning every part of that chain.
Re: HTTPS on Your Landing Page Is Important
#208Earlier quoted context omitted.
This being NatWest the penny probably still hasn’t dropped, and they’re probably trying to get him arrested for “hacking our internet”. I doubt they’ll actually implement a change. The general approach in the UK has been to not blame banks at all for poor security, and to punish anyone who finds a security issue severely.
NatWest are particularly terrible. Last time I checked, in-branch they were still using Internet Explorer to visit an http (not https) site on their intranet to launch via Java Web Start a thin client to log in to their (I assume) mainframe to actually do things. There's a number of places in that chain of events that something could go nastily wrong, despite them owning every part of that chain.
Re: HTTPS on Your Landing Page Is Important
#209Monzo [1], Starling [2], Atom [3] and Tandem [4] all manage to have HTTPS landing pages. If they can, there isn't any excuse for the more established banks not to as well. Hopefully their mobile apps use HTTPS for everything too? Apparently 35% of all UK banks have insecure landing pages. [5][6] [1] https://monzo.com [2] https://www.starlingbank.com [3] https://www.atombank.co.uk [4] https://www.tandem.co.uk [5] http…
Well, HSBC's didn't: https://threatpost.com/banking-apps-found-vulnerable-to-mitm...
Re: HTTPS on Your Landing Page Is Important
#210Earlier quoted context omitted.
When I worked for Chase on their main app, the policy for support was the current version of the browser, minus one.
To be fair Chase seems (on the surface) to have the best site/app/whatever of the major US banks. The app is pretty great.